Legal
Privacy Policy
This Privacy Policy explains how DataBurst (“DataBurst,” “we,” “us,” or “our”) collects, uses, stores, and shares information when you visit databurst.tech or use our products and applications, including DataBay and the DataBay Shopify connector (collectively, the “Services”).
1. Who we are
DataBurst provides data integration and analytics tooling that helps teams move commerce and operational data into warehouses and analytics systems they control. For privacy requests related to the Services, contact us at [email protected].
2. Information we collect
2.1 Information you provide
- Contact and demo-request details (such as name, email, company, and message content).
- Account or workspace details needed to provision and support DataBay.
- Communications you send to us by email or other channels.
2.2 Information from connected platforms (including Shopify)
When a merchant installs or authorizes a DataBurst application (such as the DataBay Shopify connector), we process store and commerce data necessary to provide the integration. Depending on the scopes granted, this may include:
- Shop identity and configuration (shop domain, locale, currency, and related settings).
- Catalog, inventory, order, fulfillment, discount, and related commerce records.
- Customer and contact details associated with those records (for example names, emails, phone numbers, and shipping addresses), when exposed by the platform and authorized by the merchant.
- Authentication credentials required to operate the integration (for example OAuth access tokens), which we store encrypted at rest.
Merchants (store owners) remain responsible for the personal data of their own customers. In that relationship, the merchant is typically the data controller and DataBurst acts as a processor / service provider for data synced through the application.
2.3 Information from Google services (Google Analytics 4 and Google Ads)
When you connect a Google account through the Services (for example, to add a Google Analytics 4 or Google Ads source to DataBay), we access that account only after you grant permission through Google’s OAuth 2.0 consent flow, and only for the scopes you approve. Depending on the scopes granted, this may include:
- Google Analytics 4 reporting data for the properties you select (such as sessions, traffic sources, events, and conversions).
- Google Ads reporting data for the accounts you select (such as campaigns, ad groups, spend, impressions, clicks, and conversions).
- OAuth tokens (including refresh tokens) required to maintain the connection, which we store encrypted at rest.
We access Google user data on a read-only basis and use it solely to provide the analytics and reporting features you requested within your own DataBay workspace. We do not create, edit, or manage Google Ads campaigns, and we do not use Google user data for advertising, retargeting, resale, credit assessment, or any purpose unrelated to the Services.
Google API Services User Data Policy — Limited Use
DataBay’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We limit our use of Google user data to providing and improving the user-facing analytics features that are prominent in the DataBay interface.
- We do not transfer or sell Google user data to third parties such as advertising platforms, data brokers, or information resellers.
- We do not use Google user data for serving ads, including retargeting, personalized, or interest-based advertising, and we do not use it to determine credit-worthiness or for lending.
- We do not allow humans to read Google user data except with your affirmative consent, for security purposes, to comply with applicable law, or on aggregated/anonymized data for internal operations.
2.4 Automatically collected technical data
- Log data such as IP address, browser type, device information, and pages visited.
- Usage and diagnostic events that help us operate, secure, and improve the Services.
- Cookies or similar technologies used for analytics (for example Google Analytics) where enabled on our website.
3. How we use information
- To provide, operate, maintain, and improve the Services.
- To authenticate integrations and sync data into destinations configured by the customer.
- To respond to demo requests, support inquiries, and account communications.
- To monitor reliability, prevent abuse, and protect the security of the Services.
- To comply with legal obligations and platform requirements (including Shopify mandatory webhooks).
We do not sell personal information.
4. How we share information
We may share information only as needed to operate the Services, including with:
- Infrastructure and cloud providers that host or process data on our behalf.
- Analytics or communication tools used to operate our website and support workflows.
- Professional advisors or authorities when required by law or to protect our rights.
- A successor entity in connection with a merger, acquisition, or asset transfer, subject to appropriate safeguards.
We do not share merchant store data or Google user data with unrelated third parties for their independent marketing purposes.
5. Data retention
We retain information for as long as needed to provide the Services, meet legal and platform obligations, resolve disputes, and enforce our agreements. Operational logs and transient events may be retained for shorter periods (for example, weeks to a few months) according to our retention schedules.
When a Shopify merchant uninstalls our application, we revoke access and process related compliance webhooks. Shopify may send a shop redaction request after uninstall; we honor applicable deletion/anonymization obligations for data under our control.
When you disconnect a Google source or revoke DataBay’s access from your Google Account permissions, we stop further syncing and delete the associated OAuth tokens. You may request deletion of previously synced Google data by emailing [email protected].
6. Security
We use administrative, technical, and organizational measures designed to protect information, including encrypted transport (HTTPS/TLS), access controls, and encryption of sensitive credentials such as OAuth tokens at rest. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
7. Your rights and choices
Depending on your location, you may have rights to access, correct, delete, or restrict processing of personal information, or to object to certain processing. To make a request, email [email protected].
If you are an end customer of a Shopify merchant using our application, please contact that merchant first. We process merchant-store customer data on the merchant’s instructions and through Shopify’s mandatory compliance webhooks (including customer data request, customer redaction, and shop redaction where applicable).
8. International transfers
We may process information in countries other than where you are located. Where required, we use appropriate safeguards for cross-border transfers.
9. Children’s privacy
The Services are intended for business users and are not directed to children under 16. We do not knowingly collect personal information from children.
10. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page reflects the latest revision. Material changes will be posted on this page.
11. Contact us
Questions about this Privacy Policy or our privacy practices:
Email: [email protected]
Website: https://databurst.tech